Automation and incident response
Threat hunting
The proactive and manual search for signs of attackers who have already bypassed the defenses, instead of passively waiting for an alarm. The analyst starts from a hypothesis and searches logs and telemetry in order to uncover threats that automated tools did not catch.
Related terms
Get CertOwl on the App Store
Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations